OptionalvalueHow the credential value is supplied. Exactly one variant may be set.
(-- Wrapped in a oneof so a non-plaintext source can be added as an
additional variant without a breaking change; secret_reference is
that variant, and further sources can follow the same way. --)
Inline plaintext credential. INPUT_ONLY: the value never round-trips on
reads. Get and List responses omit plaintext; the enclosing secret
object remains present to indicate that a secret is configured.
Reference to a customer-owned UC Secret that carries this secret value.
The value is read at invoke time under the model provider service
owner's access and is never copied onto the model provider service, so
rotating the UC Secret takes effect with no change to the model provider
service. On Create, supply secret_reference.name as
secrets/{catalog}.{schema}.{secret}.
A secret value supplied as part of an inline provider config. The caller supplies the value as inline
plaintexton writes; the platform stores it encrypted. Theplaintextfield isINPUT_ONLYand never round-trips on reads.